{"schema_version":1,"title":"Joplin vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Joplin: 3 in the last 7 days and 3 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-46650, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/joplin","json_url":"https://junglewise.ai/threats/technologies/joplin.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/joplin","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":16,"critical":0,"exploited":0,"last_7_days":3,"last_30_days":3,"last_90_days":3,"last_365_days":5},"latest":[{"cve":"CVE-2026-46650","cvss":4.4,"epss":0.003,"slug":"cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin XSS vulnerability in HTML note links","severity":"medium","exploited":false,"published_at":"2026-09-21T22:16:56.48+00:00","url":"https://junglewise.ai/threats/cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-55105","cvss":7.7,"epss":0.005,"slug":"cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin cross-site scripting in Fountain code blocks","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:05.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49453","cvss":7,"epss":0.0041,"slug":"cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin path traversal in resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2025-57798","cvss":5.5,"slug":"cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in","title":"Joplin denial of service via uncontrolled resource allocation in note titles","severity":"medium","exploited":false,"published_at":"2026-05-19T21:16:40.817+00:00","url":"https://junglewise.ai/threats/cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in"},{"cve":"CVE-2026-22810","cvss":8.2,"epss":0.0021,"slug":"cve-2026-22810-joplin-path-traversal-in-onenote-importer","title":"Joplin path traversal in OneNote importer","severity":"high","exploited":false,"published_at":"2026-05-18T21:16:39.373+00:00","url":"https://junglewise.ai/threats/cve-2026-22810-joplin-path-traversal-in-onenote-importer"},{"cve":"CVE-2023-37298","cvss":3.1,"epss":0.0057,"slug":"cve-2023-37298-joplin-cross-site-scripting-in-svg-editor","title":"Joplin Cross-site Scripting in SVG editor","severity":"low","exploited":false,"published_at":"2023-06-30T15:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-37298-joplin-cross-site-scripting-in-svg-editor"},{"cve":"CVE-2023-37299","cvss":3.1,"epss":0.0057,"slug":"cve-2023-37299-joplin-cross-site-scripting-in-html-area-tag","title":"Joplin Cross-site Scripting in HTML area tag","severity":"low","exploited":false,"published_at":"2023-06-30T15:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-37299-joplin-cross-site-scripting-in-html-area-tag"},{"cve":"CVE-2022-40277","cvss":3.1,"epss":0.0052,"slug":"cve-2022-40277-joplin-remote-code-execution-via-malicious-markdown-links","title":"Joplin Remote Code Execution via malicious markdown links","severity":"low","exploited":false,"published_at":"2022-10-01T00:00:20+00:00","url":"https://junglewise.ai/threats/cve-2022-40277-joplin-remote-code-execution-via-malicious-markdown-links"},{"cve":"CVE-2022-35131","cvss":3.1,"epss":0.0233,"slug":"cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection","title":"Joplin arbitrary code execution via node title injection","severity":"low","exploited":false,"published_at":"2022-07-26T00:00:28+00:00","url":"https://junglewise.ai/threats/cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection"},{"cve":"CVE-2021-37916","cvss":3.1,"epss":0.0073,"slug":"cve-2021-37916-joplin-cross-site-scripting-in-notes-via-form-elements","title":"Joplin Cross-site Scripting in notes via form elements","severity":"low","exploited":false,"published_at":"2022-05-24T19:09:53+00:00","url":"https://junglewise.ai/threats/cve-2021-37916-joplin-cross-site-scripting-in-notes-via-form-elements"},{"cve":"CVE-2018-1000534","cvss":3,"epss":0.0153,"slug":"cve-2018-1000534-joplin-cross-site-scripting-in-note-content","title":"Joplin cross-site scripting in note content","severity":"low","exploited":false,"published_at":"2022-05-14T03:06:11+00:00","url":"https://junglewise.ai/threats/cve-2018-1000534-joplin-cross-site-scripting-in-note-content"},{"cve":"CVE-2022-23340","cvss":3.1,"epss":0.0151,"slug":"cve-2022-23340-joplin-code-injection-remote-code-execution","title":"Joplin code injection remote code execution","severity":"low","exploited":false,"published_at":"2022-02-09T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-23340-joplin-code-injection-remote-code-execution"},{"cve":"CVE-2021-23431","cvss":3.1,"epss":0.004,"slug":"cve-2021-23431-joplin-cross-site-request-forgery-in-forms","title":"Joplin cross-site request forgery in forms","severity":"low","exploited":false,"published_at":"2021-09-02T17:09:05+00:00","url":"https://junglewise.ai/threats/cve-2021-23431-joplin-cross-site-request-forgery-in-forms"},{"cve":"CVE-2020-28249","cvss":3.1,"epss":0.0306,"slug":"cve-2020-28249-joplin-cross-site-scripting-via-link-element","title":"Joplin cross-site scripting via LINK element","severity":"low","exploited":false,"published_at":"2021-05-10T18:47:36+00:00","url":"https://junglewise.ai/threats/cve-2020-28249-joplin-cross-site-scripting-via-link-element"},{"cve":"CVE-2020-15930","cvss":3.1,"epss":0.0438,"slug":"cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag","title":"Joplin cross-site scripting in HTML embed tag","severity":"low","exploited":false,"published_at":"2021-05-07T16:29:05+00:00","url":"https://junglewise.ai/threats/cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag"},{"cve":"CVE-2020-9038","cvss":3.1,"epss":0.0357,"slug":"cve-2020-9038-joplin-cross-site-scripting-in-html-rendering","title":"Joplin cross-site scripting in HTML rendering","severity":"low","exploited":false,"published_at":"2020-10-13T17:29:25+00:00","url":"https://junglewise.ai/threats/cve-2020-9038-joplin-cross-site-scripting-in-html-rendering"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":3}],"related":[],"technology":{"hub":true,"name":"Joplin","slug":"joplin","vendor":{"name":"Joplin","slug":"joplin","url":"https://junglewise.ai/threats/vendors/joplin"},"aliases":[],"category":"application","homepage":"https://joplinapp.org/","repo_url":"https://github.com/laurent22/joplin","description":"Joplin is a free, open source note-taking and to-do application, which can handle a large number of notes organized into notebooks.","url":"https://junglewise.ai/threats/technologies/joplin"},"most_severe":[{"cve":"CVE-2026-22810","cvss":8.2,"epss":0.0021,"slug":"cve-2026-22810-joplin-path-traversal-in-onenote-importer","title":"Joplin path traversal in OneNote importer","severity":"high","exploited":false,"published_at":"2026-05-18T21:16:39.373+00:00","url":"https://junglewise.ai/threats/cve-2026-22810-joplin-path-traversal-in-onenote-importer"},{"cve":"CVE-2026-55105","cvss":7.7,"epss":0.005,"slug":"cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin cross-site scripting in Fountain code blocks","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:05.32+00:00","url":"https://junglewise.ai/threats/cve-2026-55105-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2026-49453","cvss":7,"epss":0.0041,"slug":"cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin path traversal in resource synchronization","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:03.9+00:00","url":"https://junglewise.ai/threats/cve-2026-49453-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2025-57798","cvss":5.5,"slug":"cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in","title":"Joplin denial of service via uncontrolled resource allocation in note titles","severity":"medium","exploited":false,"published_at":"2026-05-19T21:16:40.817+00:00","url":"https://junglewise.ai/threats/cve-2025-57798-joplin-denial-of-service-via-uncontrolled-resource-allocation-in"},{"cve":"CVE-2026-46650","cvss":4.4,"epss":0.003,"slug":"cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that","title":"Joplin XSS vulnerability in HTML note links","severity":"medium","exploited":false,"published_at":"2026-09-21T22:16:56.48+00:00","url":"https://junglewise.ai/threats/cve-2026-46650-joplin-is-an-open-source-note-taking-and-to-do-application-that"},{"cve":"CVE-2020-15930","cvss":3.1,"epss":0.0438,"slug":"cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag","title":"Joplin cross-site scripting in HTML embed tag","severity":"low","exploited":false,"published_at":"2021-05-07T16:29:05+00:00","url":"https://junglewise.ai/threats/cve-2020-15930-joplin-cross-site-scripting-in-html-embed-tag"},{"cve":"CVE-2020-9038","cvss":3.1,"epss":0.0357,"slug":"cve-2020-9038-joplin-cross-site-scripting-in-html-rendering","title":"Joplin cross-site scripting in HTML rendering","severity":"low","exploited":false,"published_at":"2020-10-13T17:29:25+00:00","url":"https://junglewise.ai/threats/cve-2020-9038-joplin-cross-site-scripting-in-html-rendering"},{"cve":"CVE-2020-28249","cvss":3.1,"epss":0.0306,"slug":"cve-2020-28249-joplin-cross-site-scripting-via-link-element","title":"Joplin cross-site scripting via LINK element","severity":"low","exploited":false,"published_at":"2021-05-10T18:47:36+00:00","url":"https://junglewise.ai/threats/cve-2020-28249-joplin-cross-site-scripting-via-link-element"},{"cve":"CVE-2022-35131","cvss":3.1,"epss":0.0233,"slug":"cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection","title":"Joplin arbitrary code execution via node title injection","severity":"low","exploited":false,"published_at":"2022-07-26T00:00:28+00:00","url":"https://junglewise.ai/threats/cve-2022-35131-joplin-arbitrary-code-execution-via-node-title-injection"},{"cve":"CVE-2022-23340","cvss":3.1,"epss":0.0151,"slug":"cve-2022-23340-joplin-code-injection-remote-code-execution","title":"Joplin code injection remote code execution","severity":"low","exploited":false,"published_at":"2022-02-09T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-23340-joplin-code-injection-remote-code-execution"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}